Rule Name:Missing Content-Length Header and Transfer-Encoding Header in HTTP/1.1 POST Request
Severity:mid
CVE ID:
Descripiton:
Attakers may hack the Web server making use of HTTP. The HTTP/1.1 POST requests missing Content-Length and Transfer-Encoding header are usaully from web scanner, crawler, or constructed by attackers. This rule supports to defend the A1: Broken Access Control of OWASP Top 10 - 2021. Other reference:None